Lucene search

K
ibmIBM80B33620549F962C6CA9D005F1DC2E705B98DBBA29CCE03BC75C27DC42D3606A
HistoryMay 31, 2019 - 3:45 p.m.

Security Bulletin: Apache Tomcat as used in IBM QRadar SIEM is vulnerable to denial of service (CVE-2019-0199)

2019-05-3115:45:01
www.ibm.com
29

EPSS

0.727

Percentile

98.1%

Summary

Open source Apache Tomcat vulnerable to a publicly disclosed vulnerability

Vulnerability Details

CVEID: CVE-2019-0199
**Description:**Apache Tomcat is vulnerable to a denial of service, caused by the acceptance of streams with excessive numbers of SETTINGS frames and the permitting of clients to keep streams open without reading/writing request data by the HTTP/2 implementation. By sending excessive SETTINGS frames, a remote attacker could exploit this vulnerability to cause a denial of service.
**CVSS Base Score:**7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/158637&gt; for the current score
**CVSS Environmental Score:***Undefined
**CVSS Vector:**CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products and Versions

IBM QRadar SIEM 7.3.0 - 7.3.2 Patch 1

Remediation/Fixes

QRadar / QRM / QVM / QRIF / QNI 7.3.2 Patch 2

Workarounds and Mitigations

None